The cause of failure is “GPO conflict”. Domain GPO overwrites SCCM Client settings and points the machine to corporate WSUS server. That is why Client cannot use SUP for update evaluation. It is necessary to either set GPO settings for Intranet Windows Update Server to “Not Configured” and let SCCM client configure local policy properly or put SUP FQDN and port instead of WSUS into GPO. If you are in migration and not ready to repoint all machines to SCCM you can configure GPO to repoint the settings to SCCM for SCCM clients only using WMI filter (see more here )